Once CrowdStrike's nemesis, Microsoft is now a collaborator. A shared interest in Formula 1 helped thaw the years-long fierce rivalry.

Last week, Microsoft Defender for Endpoint became the first endpoint detection and response (EDR) solution to be integrated with CrowdStrike's Falcon Next-Gen SIEM, leveraging Defender data to support third-party EDRs.
This new support lets customers use Defender telemetry and controls in CrowdStrike's Next-Gen SIEM.
"We'll tap into that and provide comprehensive security in our platform, even if they're using other endpoint technology," said CrowdStrike CTO Elia Zaitsev.
The platform now ingests data directly, accelerating Falcon's threat detection and enabling smart filtering and real-time analytics, he said.
"We can perform intelligent filtering to more efficiently manage which data is being ingested into our platform," Zaitsev said.
CrowdStrike also launched Falcon Onum to manage log data for its Next-Gen SIEM, letting Microsoft Defender telemetry be processed at scale. Onum is the company CrowdStrike acquired last year for its real-time pipeline technology.
Also for the first time, CrowdStrike's offerings are now available in the Microsoft Marketplace (formerly known as the Azure Marketplace). Most large enterprise customers that sign cloud usage agreements with Microsoft through the Microsoft Azure Consumption Commitment (MACC) can use those committed funds for third-party offerings available in the marketplace. Until last month, CrowdStrike was the only major cybersecurity platform provider whose wares were not available there. CrowdStrike has been listed in the AWS Marketplace since 2017 — a partnership that brought in $1 billion in annual revenue in 2024.
"It's a whole new ecosystem for us to partner with inside of the world of Azure and Microsoft," CrowdStrike chief business officer Daniel Bernard tells Dark Reading.
Midnight Blizzard struck in 2020 by injecting Sunburst backdoor malware in SolarWinds Orion. Kurtz called Microsoft's software "antiquated" in his testimony before the US Senate's Select Committee on Intelligence, the Congressional entity investigating that incident.
"The threat actor took advantage of systemic weaknesses in the Windows authentication architecture, allowing it to move laterally within the network," he said, noting the threat actors bypassed Microsoft's authentication schemes.
In March 2024, he told CNBC that instead of calling it a SolarWinds incident, it "really should be called the Microsoft hack because they were a big part of that compromise in terms of having their infrastructure and credentials being compromised."
Kurtz had also called out Microsoft a year earlier in the wake of an attack by a group known as Storm-0558, which exploited vulnerabilities in Microsoft Azure Active Directory (now Microsoft Entra). During that incident, hackers used stolen keys to forge authentication credentials and access the mailboxes of key government officials, including then-Secretary of Commerce Gina Raimondo.
"In an interesting way, Formula One sort of brought us together on a more strategic level," CrowdStrike chief business officer Daniel Bernard tells Dark Reading. "The certainties in life are threefold — death, taxes, and Microsoft. So rather than fight, let's find ways that customers can use all of our products, and customers want to do that."

Last week, Microsoft Defender for Endpoint became the first endpoint detection and response (EDR) solution to be integrated with CrowdStrike's Falcon Next-Gen SIEM, leveraging Defender data to support third-party EDRs.
This new support lets customers use Defender telemetry and controls in CrowdStrike's Next-Gen SIEM.
"We'll tap into that and provide comprehensive security in our platform, even if they're using other endpoint technology," said CrowdStrike CTO Elia Zaitsev.
The platform now ingests data directly, accelerating Falcon's threat detection and enabling smart filtering and real-time analytics, he said.
"We can perform intelligent filtering to more efficiently manage which data is being ingested into our platform," Zaitsev said.
CrowdStrike also launched Falcon Onum to manage log data for its Next-Gen SIEM, letting Microsoft Defender telemetry be processed at scale. Onum is the company CrowdStrike acquired last year for its real-time pipeline technology.
Also for the first time, CrowdStrike's offerings are now available in the Microsoft Marketplace (formerly known as the Azure Marketplace). Most large enterprise customers that sign cloud usage agreements with Microsoft through the Microsoft Azure Consumption Commitment (MACC) can use those committed funds for third-party offerings available in the marketplace. Until last month, CrowdStrike was the only major cybersecurity platform provider whose wares were not available there. CrowdStrike has been listed in the AWS Marketplace since 2017 — a partnership that brought in $1 billion in annual revenue in 2024.
"It's a whole new ecosystem for us to partner with inside of the world of Azure and Microsoft," CrowdStrike chief business officer Daniel Bernard tells Dark Reading.
A Vocal Critic of Microsoft
It is not entirely surprising that CrowdStrike wasn't also in Microsoft's marketplace, considering co-founder and CEO George Kurtz has been a long-time vocal critic of Microsoft. Just two years ago, Kurtz was vociferously critical of Microsoft in the days and weeks after Midnight Blizzard (also known as APT29, Cozy Bear, and Dukes), a threat group affiliated with Russian intelligence services (SVR), exploited vulnerabilities in Microsoft's software. Kurtz faulted Microsoft for a variety of "systemic failures."Midnight Blizzard struck in 2020 by injecting Sunburst backdoor malware in SolarWinds Orion. Kurtz called Microsoft's software "antiquated" in his testimony before the US Senate's Select Committee on Intelligence, the Congressional entity investigating that incident.
"The threat actor took advantage of systemic weaknesses in the Windows authentication architecture, allowing it to move laterally within the network," he said, noting the threat actors bypassed Microsoft's authentication schemes.
In March 2024, he told CNBC that instead of calling it a SolarWinds incident, it "really should be called the Microsoft hack because they were a big part of that compromise in terms of having their infrastructure and credentials being compromised."
Kurtz had also called out Microsoft a year earlier in the wake of an attack by a group known as Storm-0558, which exploited vulnerabilities in Microsoft Azure Active Directory (now Microsoft Entra). During that incident, hackers used stolen keys to forge authentication credentials and access the mailboxes of key government officials, including then-Secretary of Commerce Gina Raimondo.
Shared Interest in Formula 1
It appears a shared interest in Formula 1 car racing between the two companies led to the ultimate détente last year. Kurtz is a board member and co-owner of the Mercedes-AMG Petronas F1 team, and when Microsoft sought sponsorship, the two companies started talking."In an interesting way, Formula One sort of brought us together on a more strategic level," CrowdStrike chief business officer Daniel Bernard tells Dark Reading. "The certainties in life are threefold — death, taxes, and Microsoft. So rather than fight, let's find ways that customers can use all of our products, and customers want to do that."